Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Physical
0

CVE-2022-26390

Disclosure Date: September 08, 2022
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn’t had all data and settings erased may be able to extract sensitive information.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
4.2 Medium
Impact Score:
3.6
Exploitability Score:
0.5
Vector:
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector (AV):
Physical
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
None
Availability (A):
None

General Information

Vendors

  • baxter

Products

  • baxter spectrum iq 35700bax3 firmware -,
  • sigma spectrum 35700bax firmware -,
  • sigma spectrum 35700bax2 firmware -,
  • spectrum wireless battery module firmware,
  • spectrum wireless battery module firmware 16,
  • spectrum wireless battery module firmware 16d38,
  • spectrum wireless battery module firmware 17,
  • spectrum wireless battery module firmware 17d19

Additional Info

Technical Analysis